Doc #55624 [Csd]: session_set_save_handler should mention locking

From: Date: Mon, 17 Oct 2016 18:26:32 +0000
Subject: Doc #55624 [Csd]: session_set_save_handler should mention locking
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14024@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=55624&edit=1 ID: 55624 Updated by: yohgaki@php.net Reported by: tyrael@php.net Summary: session_set_save_handler should mention locking Status: Closed Type: Documentation Problem Package: Session related PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N New Comment: BTW, I'm going to fix session save handler's mess soon, object interface interface especially. IIRC, I've written full procedural save handler implementation many years ago that includes exclusive locks in the manual that includes precise return data types for each handler. This was removed from the manual somehow, and replaced by OO only description which lacks many aspects. I might have written this in somewhere else. It's very long time ago. Current manual page lacks create_sid, validate_sid, update_timestamp handler description, even if validate_sid handler implementation is mandatory absolutely. Since I implemented validate_sid, I'm certain that I've written manual for this. The manual page is gone also. I shall write complete manual page when save handler mess is corrected. Previous Comments: ------------------------------------------------------------------------ [2016-10-17 12:01:16] narf at devilix dot net That may be enough on the new section you've created, but this issue is explicitly about the examples on https://secure.php.net/session_set_save_handler Many users use that as a reference or just straight copy-paste from there, and there are zero mentions of locking on that page. ------------------------------------------------------------------------ [2016-10-17 11:56:05] yohgaki@php.net "Session data is locked to avoid races by default. Locking is mandatory to keep session data consistent across requests." Isn't this enough? I agree this isn't enough for beginners, though. ------------------------------------------------------------------------ [2016-10-17 11:40:46] narf at devilix dot net Why is this closed with a link to http://php.net/manual/en/features.session.security.management.php#features.session.security.management.session-locking ? The issue was about adding flock() calls to the examples on session_set_save_handler() ([1]) and warning them against the dangers of NOT using locks. It was NOT about scaring users away from locking with talks about DoS attacks. * [1] http://php.net/manual/en/function.session-set-save-handler.php ------------------------------------------------------------------------ [2016-10-17 11:21:21] yohgaki@php.net This is documented in session security section now. http://php.net/manual/en/features.session.security.management.php#features.session.security.management.session-locking ------------------------------------------------------------------------ [2013-01-16 19:26:32] googleguy@php.net Related To: Bug #63278 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=55624 -- Edit this bug report at https://bugs.php.net/bug.php?id=55624&edit=1

« previous php.doc.bugs (#14024) next »